VYPR
High severity7.5NVD Advisory· Published May 4, 2021· Updated Jun 17, 2026

CVE-2021-3154

CVE-2021-3154

Description

An issue was discovered in SolarWinds Serv-U before 15.2.2. Unauthenticated attackers can retrieve cleartext passwords via macro Injection. NOTE: this had a distinct fix relative to CVE-2020-35481.

Affected products

3
  • SolarWinds/Serv-Udescription
  • SolarWinds/Serv-U MFTllm-fuzzy2 versions
    <15.2.2+ 1 more
    • (no CPE)range: <15.2.2
    • cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*range: <15.2.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.